

It’s not clear what you mean when you say “on their own”. It wasn’t like the LLM was idle and randomly decided to start hacking. At least for the OpenAI one, it was being tested and given a task, and it determined that part of accomplishing that task was hacking another server. It was supposed to be isolated in a secure “sandbox” not connected to the internet, but found a vulnerability in some software running in the sandbox and broke out.
Edit: I should add that there are credible accusations that these companies are intentionally making it possible to break out of their test environments for publicity.


The models are tested, among other things, on their ability to turn vulnerabilities into exploits. The OpenAI scenario was exactly this.
It is a very wise practice to test these things in isolation, especially when you’re telling it to hack.
I’m not completely sold on it being a publicity stunt, personally. The law was broken by these models, and I don’t believe these companies want to start people and politicians asking the question about who is culpable when an AI breaks the law.